Again, thank you for the time you've put into researching the issue. I'm impressed.

Out of curiosity, what tool did you use to create the reports seen in your screen snapshots?

The IP belongs to Fortinet Technologies, Canada. It has been reported 15+ times for Hacking Brute Force, Web Bot Web activity, Web App Attach, etc.
Also, how are you determining the reputation of an IP address?

The default timeout for blocking receive calls in Web Installation HTTP actions is set to 10,000 milliseconds. You can increase this using the HTTP_TIMEOUT #pragma.
This change is to be made on the server, or within the Setupbuilder project?